http://www.bekkoame.ne.jp/~s_ita/index.html lists this as associated with:
W32.Mytob, Bifrose, which Symantec describes as a mass-mailing worm.

Timo Steffens

2009-10-04 18:34:27

In the last two months we noticed waves of accesses to 1863/UDP. Arbor mentions 1863 as port for C&C-servers of a small botnet. The scans (or accesses) to 1863 seem to focus on a small part of the address space (rather than cover the whole possible address space).